CVE-2008-2833
Worldlevel Le.cms < 1.4 - Authentication Bypass
Title source: ruleDescription
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/5887
References (5)
Scores
EPSS
0.0442
EPSS Percentile
88.9%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
worldlevel/le.cms
< 1.4
Timeline
Published
Jun 24, 2008
Tracked Since
Feb 18, 2026